Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/jeecgboot/JeecgBoot/issues/9691 |
|
Wed, 02 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | JeecgBoot Remote Command Execution via Groovy Script Injection | |
| Weaknesses | CWE-78 |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 26 Aug 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | JeecgBoot Remote Command Execution via Groovy Script Injection | |
| Weaknesses | CWE-78 CWE-94 |
Wed, 26 Aug 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jeecgboot
Jeecgboot jeecgboot |
|
| Vendors & Products |
Jeecgboot
Jeecgboot jeecgboot |
Wed, 26 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature of Groovy allows this blacklist to be completely bypassed through string concatenation and reflection. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-01T18:50:58.561Z
Reserved: 2026-08-17T00:00:00.000Z
Link: CVE-2026-75411
Updated: 2026-09-01T18:50:54.467Z
Status : Deferred
Published: 2026-08-26T21:16:41.097
Modified: 2026-09-01T19:17:26.930
Link: CVE-2026-75411
No data.
OpenCVE Enrichment
Updated: 2026-09-02T07:45:03Z